HIGH
SciPhi-AI
CVE published 2026-08-28
CVE-2026-82271
CVE-2026-82271 is a high-severity vulnerability in R2R versions up to 3.6.5. The issue allows authenticated users to modify conversations belonging to other users due to improper validation of user ownership in conversation update and message handlers. Attackers can manipulate conversation identifiers to rename conversations and append messages to other users' histories, potentially corrupting state and i [truncated]